Fedora 38 : openbgpd (2023-aa47d33cc8)

high Nessus Plugin ID 173419

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 38 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2023-aa47d33cc8 advisory.

# OpenBGPD 7.8

* Improved performance by optimising the output filters
* Add Autonomous System Provider Authorization (ASPA) validaton based on draft-ietf-sidrops-aspa- verification-12
* Introduce `avs` (ASPA validation state) filter and `bgpctl` filter argument
* Add ASPA support for the RTR protocol based on draft-ietf-sidrops-8210bis-10
* Improve open policy (RFC 9234) support and enable the capability automatically if a role is specified for the peer
* Introduce a per neighbor `role` configuration option to specify the session role used by ASPA verification and the open policy capability. The `announce policy` statement was simplified at the same time.
* Improve startup behaviour by introducing a small delay before opening the connection to a new peer
* Support for `aspa-set` table config which can be provided by rpki-client
* Make it possible to filter the RIB by invalid and leaked prefixes in `bgpctl` and `bgplgd`
* Add OpenMetrics output to `bgpctl` for various BGP statistics and add `/metrics` endpoint to `bgplgd`

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected openbgpd package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2023-aa47d33cc8

Plugin Details

Severity: High

ID: 173419

File Name: fedora_2023-aa47d33cc8.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/27/2023

Updated: 11/14/2024

Supported Sensors: Agentless Assessment, continuous_assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:openbgpd, cpe:/o:fedoraproject:fedora:38

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/18/2023

Vulnerability Publication Date: 3/18/2023

Reference Information